Datavant

Vulnerability & Exposure Management Engineer

Datavant$152K — $185K *
US-AnywhereRemote in United States
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in vulnerability management and application security.
  • Proficient in scripting or programming languages such as Python or Go to automate workflows.
  • Experience with application, cloud, and container security in AWS and/or Azure.
  • Knowledge of security controls and compliance frameworks like NIST and FedRAMP.
  • Ability to assess vulnerability exploitability and impact beyond numerical severity scores.
  • Strong collaborative skills to work with engineering teams on remediation efforts.
  • Excellent communication skills for conveying technical risks to diverse audiences.

Responsibilities

  • Design and implement vulnerability management capabilities focused on exploit risk reduction.
  • Build automation to prioritize and normalize vulnerability signals from multiple sources.
  • Develop dashboards and integrations for engineering teams to understand vulnerability risks.
  • Collaborate with product and engineering teams to address vulnerability findings.
  • Embed vulnerability signals into CI/CD and engineering workflows for better visibility.
  • Validate remediation efforts to ensure meaningful risk reduction.
  • Translate compliance and control requirements into technical implementations.
  • Support assessments like FedRAMP by validating technical evidence.

Benefits

  • Comprehensive total rewards strategy to support high growth and performance.
  • Opportunities for career advancement within a transformative health technology company.
  • Incentives for contributing to industry-defining data logistics products and services.
  • Health screenings and vaccination proof for post-offer compliance.
Full Job Description
What We're Looking For

A security engineer to help build and operate an engineering-driven vulnerability and exposure management program, focused on turning vulnerability data into actionable signals embedded in modern engineering workflows. This role emphasizes automation, practical risk reduction, and hands-on execution across application, cloud, and infrastructure environments. It is not primarily a ticket-tracking or audit-administration role, but a technical role contributing to scalable solutions.

What You Will Do
  • Contribute to the design, implementation, and operation of Datavant's vulnerability and exposure management capabilities, with a focus on reducing real exploit risk.
  • Build and enhance automation and workflows that ingest, normalize, and prioritize vulnerability signals across multiple sources.
  • Develop and improve engineer-facing dashboards and integrations that help teams understand and act on vulnerability risk.
  • Work with product and engineering teams to assess vulnerability findings, explain exploitability and impact, and support practical remediation or mitigation approaches.
  • Help embed vulnerability signals into existing engineering workflows (CI/CD, PRs, backlogs) to improve visibility and adoption.
  • Support validation of remediation efforts to ensure exposure is meaningfully reduced.
  • Assist in translating compliance and control requirements into scalable technical implementations.
  • Support FedRAMP and other assessments by validating technical evidence and remediation outcomes.
  • Execute technical projects that improve vulnerability visibility, prioritization, and risk reduction.
  • Contribute to improving processes, tooling, and automation within the vulnerability management program.

What You Need to Succeed
  • Solid technical experience in vulnerability management and application security, with hands-on exposure to assessing and prioritizing vulnerability findings.
  • Demonstrated ability to build or automate technical workflows using scripting or programming languages such as Python or Go.
  • Experience working with application, cloud, or container security in AWS and/or Azure environments.
  • Working knowledge of security controls and compliance frameworks (e.g., NIST, CIS, FedRAMP), with the ability to apply requirements in practical engineering contexts.
  • Ability to reason about exploitability, exposure, and impact beyond severity scores.
  • Experience collaborating with engineering teams to support remediation efforts.
  • Clear communication skills and ability to explain technical risk to varied audiences.
  • Ability to operate effectively in fast-paced environments with evolving priorities.
  • Foundational understanding of how vulnerability management fits within broader security and engineering functions.
  • Experience with commercial security tooling (e.g., SAST, SCA, cloud security platforms) and ability to interpret tool outputs critically.

What Helps You Stand Out
  • Experience building custom scripts, automations, or lightweight data pipelines to improve vulnerability visibility or prioritization.
  • Exposure to highly regulated environments (e.g., healthcare, FedRAMP Moderate/High) and participation in technical audit preparation.
  • Experience integrating vulnerability tooling into CI/CD pipelines or engineering workflows.
  • Familiarity with cloud security platforms (e.g., Wiz) or security data tooling (e.g., Snowflake, Sigma).
  • Experience using AI-assisted development tools (e.g., Claude Code) to accelerate security automation or analysis.


At Datavant our total rewards strategy powers a high-growth, high-performance, health technology company that rewards our employees for transforming health care through creating industry-defining data logistics products and services.

The range posted is for a given job title, which can include multiple levels. Individual rates for the same job title may differ based on their level, responsibilities, skills, and experience for a specific job.

The estimated total cash compensation range for this role is:

$152,000-$185,000 USD

To ensure the safety of patients and staff, many of our clients require post-offer health screenings and proof and/or completion of various vaccinations such as the flu shot, Tdap, COVID-19, etc. Any requests to be exempted from these requirements will be reviewed by Datavant Human Resources and determined on a case-by-case basis. Depending on the state in which you will be working, exemptions may be available on the basis of disability, medical contraindications to the vaccine or any of its components, pregnancy or pregnancy-related medical conditions, and/or religion.

This job is not eligible for employment sponsorship.

About Datavant

Datavant is a healthcare technology company that specializes in connecting and standardizing healthcare data from various sources. The company's products are used to improve patient care, accelerate drug development, and enhance clinical research. Datavant's platform, called the Datavant Platform, uses artificial intelligence and machine learning to identify and link patient data across different sources while maintaining patient privacy. The company was founded in 2017 by Travis May and is headquartered in San Francisco, California.
Learn more about Datavant
Size
100 employees
Industry
Founded
2017

Similar Jobs

More Jobs at Datavant

More Information Technology Jobs

Find similar Vulnerability & Exposure Management Engineer jobs: